Connect with us

NEWS

Anthropic Plants Six Engineers Inside the NSA Despite Pentagon Ban

Anthropic deployed engineers inside the NSA to run Mythos, its restricted cybersecurity AI, while fighting the Pentagon’s supply-chain ban in two federal courts.

Published

on

Anthropic has stationed roughly six engineers inside the National Security Agency to operationalize Mythos, its most powerful cybersecurity AI model, the Financial Times reported on June 5, while simultaneously contesting a federal supply-chain designation from the same Defense Department that labels the company a national security threat and bars it from Pentagon contracts.

The NSA arrangement is explicitly carved out from that ban. The engineers are already inside.

Six Engineers Inside the Agency

The engineers work as forward-deployed staff, adapting and customizing Mythos for specific operational applications inside one of the world’s most secretive intelligence agencies, the Financial Times reported. Two people familiar with the arrangement told the FT the model would be useful for infiltrating networks in countries including China and Iran. Whether the engineers or Mythos are involved in active hacking operations remains unconfirmed.

The NSA collects intelligence through wiretaps, undersea cables, corporate partnerships, and other clandestine channels, and conducts offensive cyberattacks on foreign adversaries. After Anthropic unveiled Mythos in April, senior White House officials summoned major bank executives to Washington to discuss what an AI capable of autonomous exploitation could do to financial infrastructure. The NSA’s interest runs along similar logic, directed at adversary networks.

The agency has been experimenting with AI for network exploitation since at least 2018, according to declassified budget documents. Earlier programs relied on narrow systems trained for specific tasks. Mythos, with autonomous reasoning across a full offensive pipeline, operates in a different category, capable of handling reconnaissance, vulnerability identification, and exploitation without the task-specific constraints of earlier tools.

Axios had first reported in April that the NSA was already using Mythos Preview despite the broader federal restriction on Anthropic products. That June 5 report was the first to describe on-site engineer deployment. The NSA declined to confirm or deny the reporting; Anthropic did not respond to a request for comment from TechCrunch.

The Ban and Its Exception

The $200 Million Breakdown

In July 2025, Claude became the first frontier AI model approved for use on classified US government networks, under a contract that included the Pentagon agreeing to Anthropic’s acceptable use policy. The Trump administration sought to renegotiate those terms in January 2026, demanding Anthropic accept language permitting Claude to be used for “all lawful purposes,” as part of a roughly $200 million deal. That language would have eliminated Anthropic’s two firm restrictions: the bar against using Claude for mass domestic surveillance of Americans, and the bar against fully autonomous lethal weapons systems without human oversight over targeting decisions.

Anthropic refused. Defense Secretary Pete Hegseth signed a supply-chain risk designation on February 27, 2026, placing Anthropic in regulatory territory previously reserved for foreign adversaries. Huawei and ZTE had held that classification; Anthropic became the first American company to receive it. President Trump ordered all federal agencies to immediately cease using Anthropic products, with some given a six-month phase-out window. The General Services Administration removed Anthropic from USAi.gov, the government’s centralized platform for AI model testing.

The Carve-Out That Survived

Formal designation letters arrived March 3 and 5. Anthropic filed two federal lawsuits on March 9. The NSA’s Mythos arrangement was explicitly exempt from both the designation and the subsequent litigation, per reporting from multiple outlets.

Pentagon Chief Technology Officer Emil Michael confirmed the arrangement in May, describing the Mythos deployment as “a separate national security moment.” The agency that signed the supply-chain ban and the intelligence arm running Anthropic’s model operate within the same command structure.

The key events, in sequence:

  1. July 2025: Claude approved for classified government networks, the first frontier AI model to receive that clearance
  2. January 2026: Pentagon demands “all lawful purposes” contract language; Anthropic refuses, maintaining restrictions against mass surveillance and autonomous weapons
  3. February 27, 2026: Trump orders governmentwide Anthropic purge; Hegseth signs supply-chain risk designation, the first ever applied to an American company
  4. March 3-9: Designation takes formal effect; Anthropic files lawsuits in two federal courts
  5. Late March: California federal judge grants preliminary injunction blocking broader executive enforcement
  6. April: Axios reports NSA already using Mythos Preview; D.C. Circuit denies Anthropic’s emergency stay
  7. May 19: D.C. Circuit hears oral argument; three-judge panel appears skeptical of the government’s case; ruling pending
  8. June 2: Project Glasswing expands to approximately 200 organizations across more than 15 countries
  9. June 5: Financial Times reports roughly six Anthropic engineers embedded at the NSA

What Mythos Can Do

The model Anthropic placed inside the NSA is the same one it has restricted from public release since April. Britain’s AI Security Institute (AISI), the UK government’s independent AI evaluator, tested Mythos and found it solved 73% of expert-level cybersecurity tasks that no prior AI model could complete. It also became the first AI model to finish a 32-step simulated corporate-network attack end to end.

Anthropic’s own red team documented additional capabilities:

  • Sub-$2,000: cost to run a complete exploit pipeline against a complex Linux target, completed in under one day
  • Every major operating system and web browser: scope of zero-day vulnerability discovery in directed testing, including bugs that survived decades of prior human review
  • Closed-source binaries: the model can reconstruct plausible source code from a stripped binary and scan that reconstruction for exploitable flaws, without access to the original source

Beyond those figures, Mythos can launch debuggers, interact directly with systems it analyzes, and execute code autonomously. It forms hypotheses, tests them, and iterates through a target without waiting for human input between steps. Anthropic’s red team documented using those capabilities to find firmware vulnerabilities enabling smartphone compromise and privilege escalation chains on desktop operating systems.

AISI’s published evaluation found the model executed multi-stage attacks on vulnerable networks in hours, compared to the days a human professional would need for the same tasks. Anthropic’s red team technical writeup noted the model had improved so significantly that it saturates existing cybersecurity benchmarks, requiring a shift to novel real-world security tasks to evaluate its actual limits.

Anthropic Sues the Pentagon It’s Also Helping

Anthropic filed two federal lawsuits on March 9, challenging the supply-chain designation under statutory and constitutional grounds. The California complaint raises five counts, including violation of the Administrative Procedure Act (APA), First Amendment retaliation against Anthropic’s protected speech about AI safety, and due process violations in both the designation and the unilateral contract cancellations. A Pentagon declaration had characterized Anthropic’s refusal to accept “all lawful use” language as evidence of an “adversarial posture” creating risks of “model poisoning” and “denial of service.”

Court Authority Challenged Current Status
U.S. District Court, Northern District of California 10 U.S.C. § 3252 (Pentagon supply chain exclusion authority) Preliminary injunction granted in late March, blocking broader executive enforcement
U.S. Court of Appeals, D.C. Circuit Federal Acquisition Supply Chain Security Act (FASCSA) of 2018 Emergency stay denied; oral argument concluded; ruling pending

The D.C. Circuit denied Anthropic’s emergency stay in April, saying the “equitable balance here cuts in favor of the government,” citing the stakes of managing Pentagon AI procurement during an active military conflict. The three-judge panel that heard argument on May 19 appeared skeptical of the government’s case; one judge said she had seen no evidence that Anthropic acted with bad intent. No ruling has issued.

Dozens of researchers from OpenAI and Google DeepMind filed an amicus brief in their personal capacities arguing the designation could harm US competitiveness and chill public debate on AI risks. Retired General Paul Nakasone, who led both the NSA and US Cyber Command before joining OpenAI’s board, told reporters he did not think the supply-chain designation was accurate. Legal analysts at Lawfare argued the supply-chain statute was written for hostile foreign actors covertly subverting US military systems, not for contract disputes with domestic vendors.

Glasswing’s 200 Partners

On June 2, Anthropic expanded Project Glasswing, the controlled-access program built around Mythos, from roughly 50 organizations to approximately 200 across more than 15 countries. New partners include Okta, Samsung, NATO, and ENISA, the European Union Agency for Cybersecurity. Australia’s Signals Directorate joined the expansion, extending formal government access beyond the US and UK for the first time.

Since Glasswing launched in April, partners have surfaced 10,000+ high or critical-severity security flaws. An internal Anthropic scan of 1,000 open-source projects flagged an additional 23,019 potential vulnerabilities. Major initial Glasswing partners include Apple, NVIDIA, Microsoft, CrowdStrike, and Palo Alto Networks. Anthropic committed $100 million in usage credits and $4 million in direct donations to open-source security organizations when the program launched.

The same week as the Glasswing expansion, Anthropic confidentially filed its IPO prospectus with the Securities and Exchange Commission (SEC). Annualized revenue was on track to reach $50 billion by the end of June, with a valuation near $1 trillion, per Security Affairs reporting. Through that same week, Anthropic was simultaneously contesting a federal ban in two courts, deploying engineers inside a federal intelligence agency, expanding a cybersecurity program to military alliances and foreign signals-intelligence services, and preparing to go public.

The Accountability Question

No congressional oversight of the NSA-Mythos arrangement has been publicly confirmed. No legal framework for it has been published. Pentagon CTO Emil Michael’s description of it as “a separate national security moment” is the most detailed public accounting on record, and it specified nothing about restrictions, review processes, or limits on how the engineers or the model can be used inside the agency.

Project Glasswing, the civilian side of the same Mythos rollout, requires partners to meet security requirements before gaining access and operates under Anthropic’s acceptable use policy. No equivalent public framework has been confirmed for the NSA arrangement.

Anthropic’s defense of the collaboration, relayed to the Financial Times by a person close to the company, centers on adversarial reality.

The best way to build a good defence is to build a good attack.

The person close to the company told the FT, arguing that adversaries will develop their own offensive AI regardless of Anthropic’s participation. Anthropic has also acknowledged that no company, including itself, has developed safeguards sufficient to prevent such models from being misused in ways that could cause severe harm.

Bain’s post-launch analysis of Mythos found that the vulnerabilities the model surfaces have always existed in software; what changes is the speed and cost of finding and exploiting them. That speed is now operational inside the NSA, for use against foreign networks, under an arrangement the ongoing court cases explicitly do not govern.

The D.C. Circuit’s ruling on the supply-chain designation remains pending, and the NSA arrangement sits explicitly outside whatever the court decides.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending